PT-2026-98648 · Linux · Linux Kernel

CVE-2026-97984

·

Published

2026-09-25

·

Updated

2026-10-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.21
Description An issue exists in the IPv6 implementation where a UDP length overflow can occur when using Path MTU (PMTU) discovery with an unusually large Maximum Transmission Unit (MTU). When the setsockopt IPV6 MTU DISCOVER is configured as IPV6 PMTUDISC DO or IPV6 PMTUDISC PROBE, the system may allow the maxnonfragsize to be set to the device MTU instead of the maximum allowed IPv6 MTU. If a large packet is sent over a network device with an MTU exceeding the standard limit, the resulting UDP length can overflow the 16-bit length field, triggering a warning in the udp set len short() function. This occurs specifically within the ip6 append data() function when cork->base.fragsize is not properly bounded.
Recommendations Update the Linux kernel to a version where the cork->base.fragsize is bounded to IP6 MAX MTU for UDP sockets. As a temporary mitigation, avoid setting IPV6 MTU DISCOVER to IPV6 PMTUDISC DO or IPV6 PMTUDISC PROBE on network devices with an MTU larger than the standard IPv6 maximum.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-104355
CVE-2026-97984
OPENSUSE-SU-2026:12074-1

Affected Products

Linux Kernel